Vulnerability Description
The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged editor (or above)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artplacer | Artplacer Widget | <= 2.20.6 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/afc11c92-a7c5-4e55-8f34-f2235438bd1b/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/afc11c92-a7c5-4e55-8f34-f2235438bd1b/ExploitThird Party Advisory
FAQ
What is CVE-2023-6373?
CVE-2023-6373 is a vulnerability with a CVSS score of 8.8 (HIGH). The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the la...
How severe is CVE-2023-6373?
CVE-2023-6373 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6373?
Check the references section above for vendor advisories and patch information. Affected products include: Artplacer Artplacer Widget.